From 5705340e5f5c0f6492b1168b2f6f17b51832fecd Mon Sep 17 00:00:00 2001 From: Vincent Biret Date: Fri, 9 Oct 2026 13:36:49 -0400 Subject: [PATCH] ci: ports additional validation back from yoko --- scripts/check-nuget-package-published.ps1 | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/scripts/check-nuget-package-published.ps1 b/scripts/check-nuget-package-published.ps1 index 84f45419d..0f31961ec 100644 --- a/scripts/check-nuget-package-published.ps1 +++ b/scripts/check-nuget-package-published.ps1 @@ -64,6 +64,11 @@ try { if ($null -eq $response.versions) { throw "No versions returned for NuGet $id by the private feed." } + if ($response.versions -isnot [array] -or @($response.versions | Where-Object { + $_ -isnot [string] -or $_ -notmatch '^\d[\w\.\-]*$' + }).Count -gt 0) { + throw "Invalid version list returned for NuGet $id by the private feed." + } $alreadyPublished = $response.versions -contains $version } catch { @@ -81,4 +86,4 @@ if ($alreadyPublished) { else { Write-Host "NuGet $id $version not found in the private feed; will publish via ESRP." } -Write-Host "##vso[task.setvariable variable=nugetAlreadyPublished]$($alreadyPublished.ToString().ToLowerInvariant())" +Write-Host "##vso[task.setvariable variable=nugetAlreadyPublished]$($alreadyPublished.ToString().ToLowerInvariant())" \ No newline at end of file